Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesBetter Messages

Better Messages vulnerabilities

Better Messages has 18 known vulnerabilities in this database. The most recent published record is dated 25 Sep 2026.

Known vulnerabilities
18
Active installs
10,000+
Latest version
3.0.12
Last updated
30 Sep 2026
Most recent
25 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
SQL injection
CVE-2026-93899
Medium 6.5Up to 3.0.4Fixed in a later version (latest 3.0.12)12 d ago
Cross-site scripting (XSS)
CVE-2026-94376
Medium 6.4Up to 3.0.4Fixed in a later version (latest 3.0.12)12 d ago
Authentication bypass
CVE-2026-89093
Medium 5.3Up to 2.15.33Fixed in a later version (latest 3.0.12)19 Sep 2026
Broken access control
CVE-2026-89334
Medium 6.5Up to 2.15.33Fixed in a later version (latest 3.0.12)19 Sep 2026
Cross-site scripting (XSS)
CVE-2026-18555
Medium 6.1Up to 2.15.22Fixed in a later version (latest 3.0.12)16 Sep 2026
Remote code execution
CVE-2026-16585
High 7.2Up to 2.15.19Fixed in a later version (latest 3.0.12)28 Jul 2026
Cross-site scripting (XSS)
CVE-2025-14154
Medium 6.1Up to 2.10.2Fixed in a later version (latest 3.0.12)17 Dec 2025
Sensitive data exposure
CVE-2024-13611
High 7.5Before 2.7.0Fixed in 2.7.01 Mar 2025
Server-side request forgery (SSRF)
CVE-2024-13697
Medium 4.8Before 2.7.5Fixed in 2.7.51 Mar 2025
Cross-site scripting (XSS)
CVE-2024-13612
Medium 6.4Before 2.7.0Fixed in 2.7.01 Feb 2025
Cross-site scripting (XSS)
CVE-2023-49168
Medium 6.5Before 2.4.1Fixed in 2.4.114 Dec 2023
Server-side request forgery (SSRF)
CVE-2022-41609
Medium 6.4Before 1.9.10.69Fixed in 1.9.10.6919 Nov 2022
Broken access control
CVE-2022-40216
Medium 4.3Before 1.9.10.71Fixed in 1.9.10.7118 Nov 2022
Cross-site request forgery (CSRF)
CVE-2022-36389
Medium 4.3Up to 1.9.9.148Fixed in a later version (latest 3.0.12)23 Aug 2022
Denial of service
CVE-2022-33142
High 7.7Before 1.9.10.58Fixed in 1.9.10.5823 Aug 2022
Cross-site request forgery (CSRF)
CVE-2022-29454
Low 3.1Before 1.9.9.149Fixed in 1.9.9.14920 Jul 2022
Cross-site scripting (XSS)
CVE-2021-24808
Medium 6.1Before 1.9.9.41Fixed in 1.9.9.411 Nov 2021
Cross-site request forgery (CSRF)
CVE-2021-24809
High 8.8Before 1.9.9.41Fixed in 1.9.9.411 Nov 2021
Read the published descriptions
CVE-2026-93899, 25 Sep 2026
The Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the BuddyBoss Platform plugin to be installed with its Social Groups component disabled, a state that persists on any site that has previously toggled the Groups component off since BuddyBoss does not drop the wp_bp_groups table upon deactivation. CVE record
CVE-2026-94376, 25 Sep 2026
The Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users because WordPress core's sanitize_text_field() preserves HTML-entity-encoded payloads (e.g., an iframe srcdoc attribute), allowing the encoded string to be stored as a display name without requiring the unfiltered_html capability, and the plugin subsequently decodes it server-side before rendering. CVE record
CVE-2026-89093, 19 Sep 2026
The Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check for `'ai-chat-bot-'` against a guest record's stored IP address, which is populated verbatim from the client-controlled `X-Real-IP` request header during unauthenticated guest registration. This makes it possible for unauthenticated attackers to register a guest identity that the plugin treats as its own internal AI bot, bypassing the per-room role allowlist, draft-status check, and join filters - which are all short-circuited by the bot check in `user_can_join()` and `user_can_read()` - to join administrator-restricted chat rooms, post messages into them, and read the private message history of other users. CVE record
CVE-2026-89334, 19 Sep 2026
The Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's only_joined_can_read setting retains its default value of '0'. CVE record
CVE-2026-18555, 16 Sep 2026
The Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2026-16585, 28 Jul 2026
The Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The prefix check intended to restrict deletion to the uploads directory can be bypassed by crafting a URL that begins with the legitimate uploads base URL but embeds ../ traversal sequences in the path portion, as the normalize_sticker function only applies esc_url_raw(), which does not strip ../ sequences, allowing the traversal payload to be stored verbatim in WordPress options. CVE record
CVE-2025-14154, 17 Dec 2025
The Better Messages - Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via guest display name in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-13611, 1 Mar 2025
The Better Messages - Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/bp-better-messages directory which can contain file attachments included in chat messages. CVE record
CVE-2024-13697, 1 Mar 2025
The Better Messages - Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Successful exploitation requires the "Enable link previews" to be enabled (default). CVE record
CVE-2024-13612, 1 Feb 2025
The Better Messages - Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_chat_button' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-49168, 14 Dec 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPlus Better Messages - Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss allows Stored XSS.This issue affects Better Messages - Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: from n/a through 2.4.0. CVE record
CVE-2022-41609, 19 Nov 2022
Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress. CVE record
CVE-2022-40216, 18 Nov 2022
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress. CVE record
CVE-2022-36389, 23 Aug 2022
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress. CVE record
CVE-2022-33142, 23 Aug 2022
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress. CVE record
CVE-2022-29454, 20 Jul 2022
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated. CVE record
CVE-2021-24808, 1 Nov 2021
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue CVE record
CVE-2021-24809, 1 Nov 2021
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions CVE record

What to do if you run Better Messages

If you run Better Messages, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Better Messages vulnerabilities

Free. We email you when a new vulnerability is published for Better Messages, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support